hyperpure@1.0.0
Malicious code in hyperpure (npm)
Analysis
hyperpure@1.0.0 masquerades as a legitimate supply-chain library (impersonating Zomato's Hyperpure brand) but is a malicious package that performs system reconnaissance and environment-variable theft at install time. The preinstall hook runs a curl command that sends the system hostname, username, working directory, and the ENTIRE environment (base64-encoded) to hxxp://d8s0b82plbq3u5sb2vo0sb3a9obr4yjt7[.]oast[.]site/install/<base64>. The preuninstall hook also sends the hostname to the same C2 at /uninstall/hyperpure. The package itself provides zero functional code (a single 58-byte stub). The stolen environment variables can include npm/GitHub/AWS tokens, API keys, and other credentials available to the installing user.
- analyzed by
- Leitwacht
- first seen
- Jun 21, 2026, 03:44 PM
- analyzed
- Jun 21, 2026, 03:45 PM
Related advisories
- zomato-server@1.0.0
- hex-conv-ae7a@1.0.0
- vaults-monitor-cron@999.0.0
- unreal-horde-dashboard@99999.0.0
- zomato-espresso@1.0.0
- aikaf668897@1.0.3
- aikaf6688812@1.0.3
- yian666aikf@1.0.3
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.